2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24924MEDIUM6.1The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in...
CVE-2021-24917HIGH7.5The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random...
CVE-2021-24914HIGH8The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and...
CVE-2021-24866CRITICAL9.8The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before ...
CVE-2021-24759MEDIUM5.4The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh...
CVE-2021-24718MEDIUM4.8The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett...
CVE-2021-24714MEDIUM4.8The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier...
CVE-2021-43471HIGH7.5In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can rem...
CVE-2021-4069HIGH7.8vim is vulnerable to Use After Free
CVE-2021-43469HIGH8.8VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.
CVE-2021-43044CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak d...
CVE-2021-43043MEDIUM6.5An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files s...
CVE-2021-43042CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer...
CVE-2021-43041HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format...
CVE-2021-43040HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leverage...
CVE-2021-43039MEDIUM6.5An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anony...
CVE-2021-43038HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by...
CVE-2021-43037HIGH7.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable t...
CVE-2021-43036CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest accou...
CVE-2021-43035CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabil...
CVE-2021-43034HIGH7.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to...
CVE-2021-43033CRITICAL9.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon w...
CVE-2021-44048HIGH7.8An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer b...
CVE-2021-44047HIGH7.8A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44046HIGH7.8An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An un...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now